Showing posts with label Charter of Fundamental Rights. Show all posts
Showing posts with label Charter of Fundamental Rights. Show all posts

Wednesday, January 16, 2019

EU member states attempt to circumvent CJEU rulings on data retention

One of the things the UK government is going to miss desperately, once Brexit deal is done, is the monumental amount of policy washing they have been able to drive though the EU in the past four plus decades. Not that this will prevent future UK governments from blaming the EU for whatever their prevailing set of woes happens to be.

Case in point.

The Court of  Justice of the EU has repeatedly ruled that blanket data retention is a breach of the  Charter of Fundamental rights of the EU, most notably in the Digital Rights Ireland case in April 2014 and the Tele2 case in December 2016.

Ever since, EU member state governments and various branches of EU institutions have been furiously trying to find ways to circumvent the Court's judgments and continue and expand data retention practices. They are very happy, thank you very much, with their current illegal data retention regimes.

The contortionist wordplay at large in some of the forums considering the issue is bordering on awe inspiring.

The current great hope of those working to maintain, enhance and expand data retention practices is that the planned new e-Privacy directive can be constructed in such a way as to pretend that data retention is not really data retention. In diplomatese they are working towards a more “favourable” environment for data retention than the current ePrivacy Directive of 2002. Article 15(1) of that directive when read in conjunction with the EU Charter of Fundamental Rights, rather irritatingly, for its supporters and according to the CJEU, prohibits blanket data retention. It requires data retention to be
"a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system"
Thank you to the excellent crew at EDRi for the update on the ongoing shenanigans on this today.

Monday, December 01, 2014

Email to MP re Counter Terrorism and Security Bill

The 2nd reading of Counter Terrorism and Security Bill is due in the House of Commons tomorrow.

Prompted by the Open Rights Group I've written to my MP, Nicola Blackwood, about it. Copy of my email below. Some of ORG's concerns are outlined in their briefing on the Bill.
Dear Nicola,

The latest government proposal, the Counter Terrorism and Security Bill, gives me cause for significant concern.

The ill-judged Data Retention and Investigatory Powers Act was, as you know, rushed through as emergency legislation without proper parliamentary scrutiny in the summer, the week before MPs went on holiday.  The use of the murder of Fusilier Lee Rigby as an excuse for introducing these new measures, expanding DRIPA and the further expansion of additional surveillance powers, is unconscionable.

With an election round the corner, we should hardly be surprised that party managers might be encouraging senior figures to ramp up their “tough on terrorism” rhetoric. However, Lee Rigby, who dedicated his life to defending the freedoms we enjoy in the UK, deserves better from our political leaders.

The UK survived two world wars, the cold war, multiple other military adventures and domestic bombing and violence orchestrated by groups like the IRA. Yet in the face of small numbers of violent religious extremists, successive UK governments, in the past 15 years, have normalised mass surveillance and done more damage to the legal infrastructure protecting our fundamental freedoms than any collection of deranged vicious clowns with access to dangerous weapons could do in a lifetime.

The Counter Terrorism and Security Bill is unfortunately building further on that trend.

1.       It introduces an obligation on public bodies including universities, schools, nurseries and councils to prevent terrorism. I've read this section 21 provision of the Bill repeatedly in the hope of making some sense of it. Yet the truth is, as a university educator with an interest in law and technology, I have genuinely no idea of what it is going to mean in practice.
   
2.       It expands the kind of meta-data that ISPs are being required to hold onto to help identify our IP addresses. This fundamentally misses the subtlety that an IP address denotes a device, not a human being.

3.       Mobile Phone companies do not currently log IP addresses because of differences in the technology to mainline broadband providers. They have been told they have to find a way. This will cost the taxpayer £100m over 10 years.

4.       The problems with the Bill are much wider than digital rights concerns. It also includes temporary exclusion orders, banning suspects from Britain for two years, even if they are British citizens.

5.       We are not currently facing a national emergency, so Parliament should not rush through this kind of legislation. We need proper scrutiny by MPs, Peers and civil society.

6.       The European Court of Justice (in the Digital Rights Ireland case this year) ruled that blanket data retention was incompatible with of articles 7, 8 and 52(1) of the Charter of Fundamental Rights of the EU. New laws should comply with that judgment. Neither DRIPA nor this proposed new Bill do so.

7.       The ECJ said that there should be a relationship between the data being retained and a threat to public security. However there are no restrictions to time, place or people in this Bill.

8.       DRIPA is even now the subject of a legal challenge, brought by the Open Rights Group and Liberty challenge. It may well be found illegal, while these new provisions are still being paid for.

Could I recommend for your review, the same Open Rights Group's analysis of the proposals in this Bill, available at https://www.openrightsgroup.org/ourwork/reports/briefing-on-counter-terrorism-and-security-bill  

Again you will not be surprised, given our previous correspondence, that I'm of the view that existing mass surveillance activities and powers need reigning in not expansion. Indeed the coalition government came to power on a promise of cracking down of the worst excesses of the previous government's database state. Rather than fulfilling that promise the current government has normalised and expanded these operations and powers. I hope when history comes to be written it will not judge the coalition's performance favourably on that score. Only then will we be sure that fundamental freedoms, under sustained attack by comparatively tiny numbers of terrorists and the bulk of the current, often well-intentioned but scientifically, mathematically and technically illiterate mainstream political classes, have survived intact.

Regards,

Ray

Tuesday, September 30, 2014

Which rights should we discard?

As the Tories launch into their latest 'human rights are the root of all evil' fest, at their last annual conference before the next general election, I'd like to ask David Cameron and his party colleagues a question posed by the late Lord Bingham, relating to the rights laid out in the Charter of Fundamental Rights of the European Union,
"Which of these rights, I ask, would we wish to discard? Are any of them trivial,
superfluous, unnecessary? Are any them un-British?"
Just to be clear which of -
  • Human dignity? (article 1)
  • Right to life? (article 2)
  • Right to the integrity of the person? (article 3)
  • Prohibition of torture and inhuman or degrading treatment or punishment? (article 4)
  • Prohibition of slavery and forced labour? (article 5)
  • Right to liberty and security? (article 6)
  • Respect for private and family life? (article 7)
  • Protection of personal data? (article 8)
  • Right to marry and right to found a family? (article 9)
  • Freedom of thought, conscience and religion? (article 10)
  • Freedom of expression and information? (article 11)
  • Freedom of assembly and of association? (article 12)
  • Freedom of the arts and sciences? (article 13)
  • Right to education? (article 14)
  • Freedom to choose an occupation and right to engage in work? (article 15)
  • Freedom to conduct a business? (article 16)
  • Right to property? (article 17)
  • Right to asylum? (article 18)
  • Protection in the event of removal, expulsion or extradition? (article 19)
  • Equality before the law? (article 20)
  • Non-discrimination? (article 21)
  • Cultural, religious and linguistic diversity? (article 22)
  • Equality between men and women? (article 23)
  • The rights of the child? (article 24)
  • The rights of the elderly? (article 25)
  • Integration of persons with disabilities? (article 26)
  • Solidarity (articles 27 to 38) 
  • Citizens rights (articles 39 to 46)
  • Right to an effective remedy and to a fair trial? (article 47)
  • Presumption of innocence and right of defence? (article 48)
  • Principles of legality and proportionality of criminal offences and penalties? (article 49)
  • Right not to be tried or punished twice in criminal proceedings for the same criminal offence? (article 50)
  • General provisions (articles 51 to 54)
- would the main party of government wish to discard? Are any of these rights trivial, superfluous, unnecessary? Are any them un-British?"

Wednesday, April 30, 2014

ECJ invalidate data retention directive

ECJ Invalidates data retention

On 8 April2014 the Grand Chamber of the European Court of Justice, (ECJ) in joined cases C-293/12 and C-594/12, issued a landmark decision declaring the 2006 data retention directive invalid.

The data retention directive was the instrument through which the EU required communications service providers, both fixed line and mobile, to store details of everything everyone does on the telephone or internet; for a period of between 6 months and two years. The details of what was required to be collected were laid out in article 5 of the directive and the only thing not permitted was recording of the content of calls or messages.

The ECJ decided that mass indiscriminate data retention interferes disproportionately and in a particularly serious manner with the fundamental rights to privacy and the protection of personal data.

The challengers

Digital Rights Ireland (DRI) and 11,130 Austrian citizens whose case was joined to that of DRI challenged the directive, ostensibly arguing it constituted an unlawful and unacceptable interference with fundamental rights to privacy and free speech. The Court focused on the effects of the data retention directive on articles 7 and 8 of the Charter of Fundamental Rights of the European Union - respect for private and family life and protection of personal data.

The Grand Chamber of the court proceeded to declare the directive invalid and effectively condemned pre-emptive, suspicionless, warrantless mass surveillance and consequent "interference with the fundamental rights of practically the entire European population".

Introduction and legal context

The Court opens by explaining Digital Rights Ireland challenged the implementation of the data retention directive into Irish law and the Austrian Constitutional Court, Verfassungsgerichtshof, was asked to consider the constitutionality of the Austrian implementation of the directive. They then set out the legal context.

The objective of the data protection directive, directive 95/46/EC, is to protect people's privacy. The aim of the directive on privacy and electronic communications, directive 2002/58/EC, is to harmonise privacy rights and allow sharing of data within and across the EU. Both these directives require appropriate technical and organisational measures to protect the security of personal data.  The 2002 directive prohibits surveillance without user consent, in theory. It has,however, the enormous loophole of article 15 which states any necessary, appropriate and proportionate measure can be used to bypass obligations to respect fundamental rights, when those measures are for national security or crime fighting reasons. Article 15 also specifically appears to approve of the retention of data.

The data retention directive itself obliged communications service providers to retain data. Under article 3, EU member state were required to adopt measures mandating data retention of categories of data specified in article 5. (Take a look at the list of information retained. It's almost unbelievable). Under article 4, access to this retained data would only be available to "competent national authorities" in specific cases and in accordance with national law. Article 6 specified the data should be retained for between 6 months and 2 years. Article 11 basically says when it comes to data retention the need to respect a basic level of fundamental rights theoretically noted in article 1 of the 2002 e-privacy directive could be ignored.

DRI and Austrian cases

The Court then outlines the Digital Rights Ireland and Austrian cases in paragraphs 17 to 22. DRI argued the directive constituted a disproportionate interference with fundamental rights to respect for privacy and family life, data protection and freedom of expression & information, guaranteed under articles 7, 8 and 11 of the Charter of Fundamental Rights of the European Union. Austrian citizens Mr Seitlinger, Mr Tschol et al sought the annulment of the Austrian law implementing data retention. The Austrian Court, took the view that data retention, because of the indiscriminate nature and scale of it, almost exclusively affects innocent people. The Verfassungsgerichtshof also felt data retention could not achieve its objectives and was disproportionate, so they also asked the European Court of Justice to review whether data retention constituted a disproportionate interference with fundamental rights guaranteed under articles 7, 8 and 11 of the Charter of Fundamental Rights of the European Union. Additionally the Verfassungsgerichtshof suggested the data protection directive and articles 52 and 53 of the Charter of Fundamental Rights presented barriers or at least limitations to data retention.

Next the ECJ considers the substance of the questions before them. They acknowledge (para 27) that the data mandated for retention taken as a whole provides a very rich picture of people's lives. Also that people might well adjust their behaviour and self censor due to the chilling effect of the knowledge of the mass data gathering (para 28). So there is a clear acceptance by the ECJ that freedom of expression protected by article 11 of the Charter could be on the line. They do not however pursue this to any solid conclusion and focus instead of matters of privacy and data protection, relating to articles 7 & 8 of the Charter.

Interference with privacy and data protection

The heavy lifting in the decision is then laid out from paragraph 32 to 71.
"32. ... Directive 2006/24... derogates from the system of protection of the right to privacy established by Directives 95/46 and 2002/58"
The data collected does not have to be sensitive or to inconvenience people in any way to establish the existence of an interference with the fundamental right to privacy. (Para 33). Data retention
"constitutes in itself an interference with the rights guaranteed by Article 7 of the Charter." (para 34). Access to the data retained by competent national authorities is an interference with the rights guaranteed by Article 7 of the Charter. (para 35). Likewise because the directive provides for the processing of personal data it is an interference with the fundamental right to data protection covered by article 8 of the Charter. (para 36). Paragraph 37 merits quotation in full:
"37.  It must be stated that the interference caused by Directive 2006/24 with the fundamental rights laid down in Articles 7 and 8 of the Charter is, as the Advocate General has also pointed out, in particular, in paragraphs 77 and 80 of his Opinion, wide-ranging, and it must be considered to be particularly serious. Furthermore, as the Advocate General has pointed out in paragraphs 52 and 72 of his Opinion, the fact that data are retained and subsequently used without the subscriber or registered user being informed is likely to generate in the minds of the persons concerned the feeling that their private lives are the subject of constant surveillance."
Justification for interference with fundamental rights

Having declared the interference with the fundamental rights to privacy and data protection particularly serious, the Court then must look at the justification for and proportionality of this interference. It finds the 2006 directive wanting on both counts.

Article 52(1) of the Charter of Fundamental Rights of the EU states that any circumvention of those rights must be proportionate, strictly limited and necessary to meet objectives of general interest or to protect the freedoms of others.

In paragraphs 39 and 40, the Court then makes a rather fuzzy attempt to step back from the absolutist stance it appears to have be shaping up to take against data retention.
"39... it must be held that, even though the retention of data required by Directive 2006/24 constitutes a particularly serious interference with those rights, it is not such as to adversely affect the essence of those rights given that, as follows from Article 1(2) of the directive, the directive does not permit the acquisition of knowledge of the content of the electronic communications as such."
This does not sit logically with the earlier acceptance in paragraphs 27 & 28 that metadata provides a very comprehensive picture of peoples' lives which could have a chilling affect on freedom of expression. It also seems something of a non sequitur - how must it be held that data retention constitutes a particularly serious interference with fundamental rights, yet not be such as to adversely affect the essence of those rights?

Paragraph 40 says the essence of article 8 data protection rights are not adversely affected because the text of data retention directive includes a note that says data protection must be respected. On that basis you could stick a token 'respect data protection' clause in every liberty bashing regulatory instrument and not "adversely affect" data protection.

The object of the the data retention is to fight serious crime and article 6 of the Charter of rights lays down the fundamental right to security. So fighting serious crime is a legitimate 'objective of general interest.' And communications technology is an important crime fighting tool. So
"44.  It must therefore be held that the retention of data for the purpose of allowing the competent national authorities to have possible access to those data, as required by Directive 2006/24, genuinely satisfies an objective of general interest."
Disproportionate nature of the data retention directive

The objective of data retention is acceptable. But is data retention a proportionate way to achieve that crime fighting objective? Proportionality requires acts of EU institutions to "not exceed the limits of what is appropriate and necessary in order to achieve" the objective in hand, in this case fighting serious crime.

The ECJ takes guidance from the European Court of Human Rights decision in 2008, S and Marper v UK, on the retention of DNA and fingerprints.
"47. ... the EU legislature’s discretion may prove to be limited, depending on a number of factors, including, in particular, the area concerned, the nature of the right at issue guaranteed by the Charter, the nature and seriousness of the interference and the object pursued by the interference (see, by analogy, as regards Article 8 of the ECHR, Eur. Court H.R., S. and Marper v. the United Kingdom [GC], nos. 30562/04 and 30566/04, § 102, ECHR 2008-V)."
Privacy and data protection are fundamental and so the discretion of EU legislature to interfere with them is reduced and any review of that discretion should be strict. (para 48). Data retention may be appropriate for crime fighting. (Para 49). The fight against serious crime requires modern techniques but that doesn't mean the kind of mass data retention required by the directive is necessary. (Para 51). Data protection is especially important for privacy.
"54. Consequently, the EU legislation in question must lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards so that the persons whose data have been retained have sufficient guarantees to effectively protect their personal data against the risk of abuse and against any unlawful access and use of that data (see, by analogy, as regards Article 8 of the ECHR, Eur. Court H.R., Liberty and Others v. the United Kingdom, 1 July 2008, no. 58243/00, § 62 and 63; Rotaru v. Romania, § 57 to 59, and S. and Marper v. the United Kingdom, § 99)."
Data retention should have clear rule on scope and application and minimum safeguards against unlawful access. The unstated critique is that the directive fails on all counts.
"55.  The need for such safeguards is all the greater where, as laid down in Directive 2006/24, personal data are subjected to automatic processing and where there is a significant risk of unlawful access to those data (see, by analogy, as regards Article 8 of the ECHR, S. and Marper v. the United Kingdom, § 103, and M. K. v. France, 18 April 2013, no. 19522/09, § 35)."
Safeguards are particularly important with respect to the automatic large scale processing of data. Again the 2006 directive fails.
56. ... Directive 2006/24... entails an interference with the fundamental rights of practically the entire European population. [My emphasis]
"57.   In this respect, it must be noted, first, that Directive 2006/24 covers, in a generalised manner, all persons and all means of electronic communication as well as all traffic data without any differentiation, limitation or exception being made in the light of the objective of fighting against serious crime.." [My emphasis]
Paragraph 58 goes on to criticise Directive 2006/24's mandate to engage in the mass surveillance of innocent people not remotely connected to serious crime. Additionally it circumvents rules protecting privileged communications.

Then in recognition of the need for targeted rather than mass surveillance they state:
"59.  Moreover, whilst seeking to contribute to the fight against serious crime, Directive 2006/24 does not require any relationship between the data whose retention is provided for and a threat to public security and, in particular, it is not restricted to a retention in relation (i) to data pertaining to a particular time period and/or a particular geographical zone and/or to a circle of particular persons likely to be involved, in one way or another, in a serious crime, or (ii) to persons who could, for other reasons, contribute, by the retention of their data, to the prevention, detection or prosecution of serious offences."
That paragraph alone could be interpreted as a serious judicial uppercut to the UK government's mass surveillance practices revealed by Edward Snowden. At the risk of being boring I'm going to repeat my old mantra here.  It is unnecessary and completely disproportionate, not to mention dangerously ineffective, to collect innocent communications in order to find serious criminals. Finding a terrorist or serious criminal is a needle in a haystack problem – you can’t find the needle by throwing infinitely more needle-less electronic hay on the stack.  Law enforcement, intelligence and security services have to be able to move with the times. They need to use modern digital technologies intelligently in their work and through targeted data preservation regimes – not the mass surveillance regime they are currently operating – engage in technological surveillance of individuals about whom they have reasonable cause to harbour suspicion. That is not, however, the same as building an infrastructure of mass surveillance or facilitating the same through the legal architecture of directives like 2006/24 on data retention.

The ECJ follows up this mass surveillance critique with a clear declaration in paragraph 60 that the data retention directive has no limits on access to and use of retained data to the purpose of fighting serious crime and no criteria for determining such limits. In a way paragraphs 60 to 68 provide a blueprint for the Commission and particularly rabid surveillance addicted governments to re-write the data retention directive in a way that might be acceptable to the ECJ. Since these paragraphs spell out what is missing from the directive and might be read as suggesting 'make a token effort with these things next time and you'll be ok.'

Para 61 criticises Directive 2006/24's lack of procedures on determining access to data or its use or even limiting these to crime fighting. Para 62 notes the directive does not limit the number of people with access to the retained data to those strictly necessary. Nor does it subject access to the data to the prior review or oversight of a court, in order to limit access to that which is strictly necessary. Nor are member states obliged to set down such procedures.

Para 63 complains that the blanket data retention mandated doesn't make any distinction between categories of data. Para 64 says there is not even an attempt to justify the arbitrary period of retention chosen of between 6 months and 2 years.

Then comes the clincher.
"65.  It follows from the above that Directive 2006/24 does not lay down clear and precise rules governing the extent of the interference with the fundamental rights enshrined in Articles 7 and 8 of the Charter. It must therefore be held that Directive 2006/24 entails a wide-ranging and particularly serious interference with those fundamental rights in the legal order of the EU, without such an interference being precisely circumscribed by provisions to ensure that it is actually limited to what is strictly necessary." [My emphasis]
"66.   Moreover, as far as concerns the rules relating to the security and protection of data retained by providers of publicly available electronic communications services or of public communications networks, it must be held that Directive 2006/24 does not provide for sufficient safeguards, as required by Article 8 of the Charter, to ensure effective protection of the data retained against the risk of abuse and against any unlawful access and use of that data. In the first place, Article 7 of Directive 2006/24 does not lay down rules which are specific and adapted to (i) the vast quantity of data whose retention is required by that directive, (ii) the sensitive nature of that data and (iii) the risk of unlawful access to that data, rules which would serve, in particular, to govern the protection and security of the data in question in a clear and strict manner in order to ensure their full integrity and confidentiality. Furthermore, a specific obligation on Member States to establish such rules has also not been laid down." [My emphasis]
Para 67 says the 2006 directive doesn't specify a high enough data security threshold and doesn't require the irreversible destruction of data at the end of the retention period. Then in 68 the ECJ has serious concerns that the data retention directive does not require data to be retained within the borders of the EU. So control by independent authority of data protection and access to the retained data cannot be fully ensured. Such control is an essential corner stone of EU data protection law.

And that's the ballgame

They conclude:
"69. Having regard to all the foregoing considerations, it must be held that, by adopting Directive 2006/24, the EU legislature has exceeded the limits imposed by compliance with the principle of proportionality in the light of Articles 7, 8 and 52(1) of the Charter.
70. In those circumstances, there is no need to examine the validity of Directive 2006/24 in the light of Article 11 of the Charter.
71.  Consequently... Directive 2006/24 is invalid."
In short, the data retention directive presents a disproportionate interference with the fundamental rights to respect for private and family life and the protection of personal data. Consequently the directive is invalid, null and void. And because it is invalid on privacy grounds the ECJ don't see the need to pursue the question of whether it also might be invalid on the grounds of Article 11 of the Charter of Fundamental Rights relating to freedom of expression.

If the Charter of Fundamental Rights proves to have staying power as the legislative architecture protecting the rights of EU citizens into the distant future, then this ECJ decision could well prove to be historic. On a par with the civil rights cases of the US Supreme Court such as Brown v the Board of Education or the NYT v Sullivan. Only time will tell whether it achieves that fame or notoriety but it was certainly a welcome development in the battle to avoid a mass surveilled future.

Congratulations and thanks to TJ McIntyre, Simon McGarr and Digital Rights Ireland and to Mr Seitlinger, Mr Tschol et al and the Austrian Constitutional Court the Verfassungsgerichtshof in what was a long and difficult battle and a hard fought but very welcome victory in the end. 

Tuesday, April 29, 2014

Free is a lie - Aral Balkan at TNW

Take 32 mins and listen to Indie phone's Aral Balkan's talk at the recent TNW conference.



Balkan opens with a simple thought experiment. He's setting up a hypothetical business, Schnail Mail, which will solve the problem of mail delivery by delivering letters and parcels of all shapes and sizes anywhere in the world for free. He asks his audience how many of them would sign up for it. Sounds like an attractive enterprise so many would. In the interests of full disclosure he then explains that by the way Schnail mail will open and forensically examine all letters and parcels to learn about their customers, obviously in the interests only of offering them a better service. How many would now sign up? Not very many though there were still a hard core half a dozen or so. In any case the Schnail Mail business model is the Google, Facebook, [big tech co of choice] "free" service business model.

The business model of "free" is the business model of mass surveillance. We effectively hand over quarries of personal data for these corporations to mine for their own ends. He quotes Eric Schmidt noting Google knows who you are, where you are and what you are thinking; and Facebook knowing people are on the path to a relationship before those people possibly even know it themselves.

He also quotes the Google executive chairman saying:
"If you have something you don't want everyone to know maybe you shouldn't be doing it in the first place."
That's not the kind of world Balkan wants. Privacy is not about whether you have something to hide. It's about having control of what you want to share and what to keep to yourself. But in the world of "free" mass surveillance you don't have that control. The corporations do and they have acquired that control by deceit because consumers largely have no idea of the information they have surrendered/bartered in exchange for "free" services.  If we make the panopticon the default that leads to a society where anything we want to keep private has an association of guilt attached. Privacy becomes only about hiding bad things. Balkan rejects that notion.

Ordinary consumers currently have no choice - all roads lead to digital feudalism regardless of which corporate walled garden is chosen. Techies say use free and open source alternatives. But ordinary mortals have not got the time, skills or resources to architect or build our own FOSS, experience-led digital privacy assured shells to shield our rich personal data quarries / digital personas, thereby enabling us to participate in the information society without compromising our privacy. So techies, entrepreneurs, the market have to start to provide custom built user friendly privacy enhanced technologies. One such effort is Balkan's indie phone.

The true cost of "free" he says is our privacy, our civil liberties, our human rights.

Good luck to Mr Balkan with his indie phone venture. His success will likely depend on the degree to which he can manage the pathological calculus that is -

Privacy vs Convenience/attraction/gratification/access/community/conformity/convenience
- in addition to the small matter of taking on the power of the mass surveillance addicted market incumbents.

Thursday, April 10, 2014

European Court of Justice annuls 2006 data retention directive

On Tuesday, 8 April, 2014, the Court of Justice of the European Union, (also known as the European Court of Justice) in a scathing indictment of widespread mass surveillance practices, abolished the 2006 EU data retention directive. The Court said the directive was a serious and unjustified interference with the fundamental right to privacy enshrined in Article 7 of the EU Charter of Fundamental Rights.

The directive constituted such a serious interference with the fundamental right to privacy that it had to be annulled - it was an affront to liberty that should never have existed.

TJ McIntyre of Digital Rights Ireland (DRI), the heroic litigants in chief, has made a copy of the full decision available at scribd and it will appear on the Court website in due course. Credit also to the 11,130 Austrian citizens whose case was joined to that of DRI since they had challenged the directive on similar grounds.

For the uninitiated, the data retention directive was the instrument through which the EU required communications service providers, both fixed line and mobile, to store details of everything everyone does on the telephone or internet; for a period of between 6 months and two years. The details of what should be collected are laid out in article 5 of the directive and the only thing not allowed was recording of the content of calls or messages.

It's actually worth spending 5 or 10 minutes looking at that list of things in Article 5 that has been gathered by communications service providers throughout the EU. At first pass it seems a bit legalistic but if you cut through that and think about it – names, addresses, who spoke to whom, where, when, for how long, on what device, how often, websites visited etc. etc. This all paints a very detailed picture and most people don’t know it is going on. The who, where, why, how, what and when of individual lives is all there in this metadata.

With what may be interpreted as half and eye on the Edward Snowden revelations, the Grand Chamber of the Court, effectively condemned pre-emptive, suspicionless, warrantless mass surveillance and consequent "interference with the fundamental rights of practically the entire European population". The case is the first major court decision on mass surveillance since the Snowden stories started to break in June 2013. Though high courts in Romania (2009), Germany (2010), Bulgaria (2010),  the Czech Republic (2011) and Cyprus (2011) have all declared the data retention directive unconstitutional and/or a disproportionate unjustified interference with the fundamental right to privacy, free speech and confidentiality of communications. As recently as 2011 following the national courts' striking down of regulations implementing data retention, the European Commission were hounding Germany and Romania to re-implement the directive. The Commission subsequently sued Romania which went on to pass a widely criticised version of data retention law in 2012, nicknamed "Big Brother". The Commission had also previously sued Greece, the Netherlands, Austria and Sweden for failing to implement the directive by the due date of September 15 2007.

The previous UK Labour government were one of the key driving forces behind the original implementation of the the data retention directive. The current UK government is one of the biggest cheerleaders for and operators of mass surveillance standards and practices. Though the UK government was not involved directly in the case, (and are scrambling madly to find a way to circumvent the decision as, sadly, are the Commission), both the current and the previous administrations' behavior, in the data retention context, is considered so heinous in law that it should never have happened; and the laws facilitating that behavior should never have existed.

Some commentators have also suggested the Court was firing a message not just to the UK but across the pond (2 min 40sec audio) to the effect that US mass surveillance standards are totally unacceptable in an EU context.

I have now managed to read the decision in full (in fits and starts) and will endeavour to post an analysis here at the earliest opportunity. (Aka when grown up admin duties allow and I can construct a sufficiently robust buffer between me and the zombiecrats to take a sustained run at it).